diff --git a/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md b/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md index 35d3320..12baf0b 100644 --- a/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md +++ b/workplans/KEY-WP-0004-binky-hedgehog-tenant-onboarding.md @@ -34,7 +34,7 @@ profile's `client_credentials`/workload-identity grant for service accounts v0.2 tenant + service-account claim rules (already ratified canon — no new profile work needed, this is provisioning against an existing contract), and the cross-repo runtime direction now tracked in -`railiance-master/workplans/RAILIANCE-WP-0019-knative-qonto-runtime-on-reef-railiance.md`. +`railiance-master/workplans/RMASTER-WP-0019-knative-qonto-runtime-on-reef-railiance.md`. This workplan no longer targets a permanent direct `qonto-assistant` deployment shape. Its workload-identity lane is intended for the future @@ -324,7 +324,7 @@ token (future qonto runtime client, with any temporary `qonto-assistant` bridge explicitly recorded) both resolve to `tenant:friendly:binky` and nothing else; the credential lane is discoverable via `warden access` without Bernd touching key-cape/OpenBao admin surfaces directly. The runtime follow-up -then continues in `QONTO-WP-0004` and `RAILIANCE-WP-0019`. Run +then continues in `QONTO-WP-0004` and `RMASTER-WP-0019`. Run `statehub fix-consistency`. 2026-07-29 closure: T01–T05 are complete, T06 is intentionally cancelled,